First published: Wed Jan 12 2011(Updated: )
Buffer overflow in the MAC-LTE dissector (epan/dissectors/packet-mac-lte.c) in Wireshark 1.2.0 through 1.2.13 and 1.4.0 through 1.4.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of RARs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | =1.2.7 | |
Wireshark Wireshark | =1.2.11 | |
Wireshark Wireshark | =1.2.10 | |
Wireshark Wireshark | =1.2.6 | |
Wireshark Wireshark | =1.2.8 | |
Wireshark Wireshark | =1.2.0 | |
Wireshark Wireshark | =1.2.3 | |
Wireshark Wireshark | =1.2.12 | |
Wireshark Wireshark | =1.2.13 | |
Wireshark Wireshark | =1.2.5 | |
Wireshark Wireshark | =1.2.1 | |
Wireshark Wireshark | =1.2.4 | |
Wireshark Wireshark | =1.2 | |
Wireshark Wireshark | =1.2.9 | |
Wireshark Wireshark | =1.2.2 | |
Wireshark Wireshark | =1.4.2 | |
Wireshark Wireshark | =1.4.0 | |
Wireshark Wireshark | =1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0444 has a severity rating of potentially critical due to its ability to cause denial of service and possible arbitrary code execution.
To fix CVE-2011-0444, upgrade to a patched version of Wireshark, specifically versions 1.2.14 or 1.4.3 and above.
CVE-2011-0444 affects Wireshark versions 1.2.0 through 1.2.13 and 1.4.0 through 1.4.2.
CVE-2011-0444 can be exploited by remote attackers using a large number of RARs which can lead to crashes.
As a workaround for CVE-2011-0444, users should refrain from opening suspicious or untrusted RAR files until the software is updated.